Back to all stories

AI in Cybersecurity: Faster Discovery, But Backlogs Are the New Challenge

AI-driven tools are transforming cybersecurity by enabling faster detection of vulnerabilities, but they’re also creating a new challenge: a massive backlog of unresolved issues. While security teams on HackerOne’s platform have cut the time to fix critical vulnerabilities by roughly half, the volume of findings has overwhelmed validation and remediation processes.

LA

LazyFounders

·5 min read
AI in Cybersecurity: Faster Discovery, But Backlogs Are the New Challenge
Image: (Image credit: Blue Planet Studio/Shutterstock) via TechRadar

AI-driven tools are transforming cybersecurity by enabling faster detection of vulnerabilities, but they’re also creating a new challenge: a massive backlog of unresolved issues. While security teams on HackerOne’s platform have cut the time to fix critical vulnerabilities by roughly half, the volume of findings has overwhelmed validation and remediation processes.

30 SEC SUMMARY

  • AI-driven security tools are accelerating vulnerability detection, reducing the time to fix critical issues by about 50% for teams on HackerOne’s platform.
  • The same tools are causing a nearly 29-fold increase in backlogs of unresolved vulnerabilities, overwhelming security teams.
  • AI excels at scaling discovery but fails to address validation, prioritization, and remediation, creating new bottlenecks.
  • Continuous Threat Exposure Management (CTEM) aims to balance discovery and remediation by integrating these processes.
  • Researchers who demonstrate business impact and exploitability are earning more, with payouts up 25% year-on-year.

TABLE OF CONTENTS

  • AI Accelerates Vulnerability Detection, Creates Backlogs
  • The Bottleneck: Validation and Remediation
  • CTEM as a Solution to AI-Driven Overload
  • The Rising Value of Human Expertise
  • Metrics That Matter: From Activity to Risk Reduction
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • AI reduces the time to fix critical vulnerabilities by roughly 50% for security teams on HackerOne’s platform.
  • The backlog of unresolved critical vulnerabilities grew nearly 29-fold due to AI-driven discovery tools.
  • Continuous Threat Exposure Management (CTEM) aims to integrate discovery, validation, and remediation into a unified process.
  • Researchers on HackerOne earned over $47 million in the first half of the year, a 25% year-on-year increase.
  • AI accelerates discovery but fails to address validation and prioritization, creating new bottlenecks.

AI Accelerates Vulnerability Detection, Creates Backlogs

Security teams using HackerOne’s platform have reduced the time to fix critical vulnerabilities by roughly 50% over the past year, according to reporting by TechRadar. This improvement is attributed to the adoption of AI-driven tools that accelerate the discovery of security weaknesses.

The Bottleneck: Validation and Remediation

The same tools responsible for faster detection have also led to a nearly 29-fold increase in the backlog of unresolved critical vulnerabilities. According to TechRadar, this surge is overwhelming security teams, who struggle to validate, prioritize, and remediate the flood of findings.

AI’s strength lies in its ability to test software at a scale unattainable by manual processes. However, this advantage is double-edged: while vulnerabilities are surfaced earlier and faster, the tools do little to address the subsequent steps of validation and remediation. As a result, organizations are becoming "busier" without necessarily becoming more secure.

CTEM as a Solution to AI-Driven Overload

To address this imbalance, the concept of Continuous Threat Exposure Management (CTEM) has gained traction. CTEM proposes a continuous cycle of discovering attack surfaces, identifying weaknesses, proving exploitability, and directing remediation efforts. According to TechRadar, this framework aims to bridge the gap between discovery and action, ensuring that findings translate into reduced risk.

The Rising Value of Human Expertise

Human expertise remains critical in the era of AI-driven security. Researchers on HackerOne’s platform earned over $47 million in the first half of this year, a 25% increase compared to the same period last year. The highest earners are those who can demonstrate the business impact of vulnerabilities and provide proof of exploitability.

As AI takes over routine findings, researchers who can chain weaknesses, reason about business logic, and produce credible evidence of threats are becoming even more valuable. This trend underscores the limitations of AI in areas requiring judgment and creativity.

Metrics That Matter: From Activity to Risk Reduction

Organizations are being urged to shift their focus from activity-based metrics, such as the number of vulnerabilities discovered, to measures of risk reduction. According to TechRadar, boards and executive teams increasingly demand metrics that reflect tangible improvements in security posture, rather than mere busyness.

What this means

LazyFounders analysis — our interpretation, not reported fact.

AI is transforming cybersecurity by making vulnerability discovery faster and more scalable, but it’s also exposing a critical gap: the ability to act on findings. For founders and operators, this means investing in AI-driven discovery tools is only the first step. The real advantage lies in building or integrating systems that validate, prioritize, and remediate vulnerabilities efficiently.

Startups in this space should focus on solutions that bridge the gap between discovery and action, such as CTEM platforms or automation tools that reduce analyst workload. Metrics like risk reduction and time-to-remediation will matter more than ever, especially as boards and executives demand tangible outcomes.

The rise in researcher payouts also signals an opportunity: human expertise remains irreplaceable for complex threats. Combining AI’s scale with human judgment could be the key to staying ahead.

Key takeaways

  • AI-driven tools are cutting the time to detect critical vulnerabilities by roughly 50%, but they’re also overwhelming teams with a 29-fold increase in backlogs.
  • The value of AI in cybersecurity lies not just in finding vulnerabilities but in improving validation, prioritization, and remediation processes.
  • Continuous Threat Exposure Management (CTEM) offers a framework to integrate discovery, validation, and remediation into a unified workflow.
  • Researchers who can demonstrate business impact and exploitability are becoming more valuable, with earnings on HackerOne’s platform up 25% year-on-year.
  • Organizations must shift from activity-based metrics (e.g., finding counts) to risk-reduction measures to align with executive and board expectations.

FAQ

What is Continuous Threat Exposure Management (CTEM)?

CTEM is a framework designed to continuously identify, validate, prioritize, and remediate vulnerabilities. It aims to integrate these processes into a unified workflow to reduce risk and improve security outcomes.

Why are backlogs of vulnerabilities growing despite faster detection?

AI-driven tools excel at discovering vulnerabilities at scale but do not address the subsequent steps of validation, prioritization, and remediation. This imbalance leads to a growing backlog of unresolved issues.

How can organizations measure the effectiveness of their security efforts?

Instead of focusing on activity-based metrics like the number of vulnerabilities found, organizations should prioritize risk reduction measures. These include time-to-remediation, reduction in exploitable vulnerabilities, and overall improvements in security posture.

Related on LazyFounders

Sources

  1. TechRadar · 2026-09-23
    AI floods security teams with findings. The advantage is in what happens next

This story is an original summary and analysis written by LazyFounders from the reporting listed above. Facts are attributed to their original publishers; sections marked as analysis are LazyFounders's opinion. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links.

Lazy Founder - Powered by Blogy.in